2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59110 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechani... |
| CVE-2025-55179 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.2... |
| CVE-2025-13349 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown p... |
| CVE-2025-13347 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of t... |
| CVE-2025-13346 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the f... |
| CVE-2025-12545 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is... |
| CVE-2025-12376 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request ... |
| CVE-2025-10158 | MEDIUM | 4.3 | 0.3% | Nov 18, 2025 | A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based bu... |
| CVE-2025-6670 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method... |
| CVE-2025-41350 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store... |
| CVE-2025-41349 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store... |
| CVE-2025-41348 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover,... |
| CVE-2025-13345 | HIGH | 8.8 | 0.4% | Nov 18, 2025 | A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue ... |
| CVE-2025-13344 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a... |
| CVE-2025-13343 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function o... |
| CVE-2025-41737 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules. |
| CVE-2025-41736 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th... |
| CVE-2025-41735 | HIGH | 8.8 | 0.5% | Nov 18, 2025 | A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem... |
| CVE-2025-41734 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices. |
| CVE-2025-41733 | CRITICAL | 9.8 | 0.6% | Nov 18, 2025 | The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthentica... |
| CVE-2025-41347 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerabili... |
| CVE-2025-11427 | MEDIUM | 5.8 | 0.4% | Nov 18, 2025 | The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forg... |
| CVE-2025-4212 | HIGH | 7.2 | 0.2% | Nov 18, 2025 | The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl... |
| CVE-2025-41346 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impers... |
| CVE-2025-13196 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Str... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now